Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2026-13767

The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is …

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.4
CVE-2026-13755

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute …

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-13754

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, a…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.8
CVE-2026-13741

The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,…

Mitigation only
Fix from $1,950 2026-07-16
Unclassified CRITICAL 9.2
CVE-2026-15925

Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacke…

No fix yet
Fix from $2,300 2026-07-16
Unclassified MEDIUM 5.5
CVE-2026-12979

The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, all…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.1
CVE-2026-12978

The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its p…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.1
CVE-2026-12869

The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-12684

The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.1
CVE-2026-12585

The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the …

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.8
CVE-2026-12525

The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing …

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.9
CVE-2026-12510

The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, al…

No fix yet
Fix from $1,600 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-12492

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authent…

No fix yet
Fix from $2,300 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-12395

The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authentic…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 5.4
CVE-2026-11866

The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.1
CVE-2026-11371

The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the featu…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.1
CVE-2026-15306

The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via …

No fix yet
Fix from $1,600 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-15013

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all version…

No fix yet
Fix from $2,300 2026-07-16
Unclassified HIGH 7.2
CVE-2026-13042

The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 …

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.5
CVE-2026-21729

Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strat…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.4
CVE-2026-15652

The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Blo…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.4
CVE-2026-14987

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-12941

The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'orde…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.5
CVE-2026-12753

The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' p…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.8
CVE-2026-3842

A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This o…

No fix yet
Fix from $1,950 2026-07-16
Build Of Keycloak HIGH 8.1
CVE-2026-1609

A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak f…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.3
CVE-2026-15909

A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the fil…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.3
CVE-2026-15907

A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Exe…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.7
CVE-2026-45313

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc…

Mitigation only
Fix from $1,950 2026-07-15
Nanomq HIGH 7.5
CVE-2026-36590

An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component

Mitigation only
Fix from $1,950 2026-07-15